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' A new quantum cryptography protocol, based on all unselected states of a 

■ qubit as a sort of alphabet with continuous set of letters, is proposed. Its 

effectiveness is calculated and shown to be essentially higher than those of 
the other known protocols. 
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I. INTRODUCTION 



Quantum cryptography (QC) could well be the first practical application of the rapidly 
developing field of quantum information [1]. Since 1970s when the idea of QC was proposed 
first [1,2] a number of different protocols implementing it have been suggested [3-6]. Despite 
their diversity all of them are based on a bcaTitiful idea employing a basic principle of quan- 
tum mechanics — no-cloning (or impossibility to copy) quantum states [7]. Thanks to this, 
an eavesdropper cannot intercept the quantum communication channel without disturbing 
a transmitting message if it contains a set of incompatible, i.e., essentially quantum, not 
governed by the rules of classical logic, states. Moreover, any attempt to copy this set of 
states inevitably disturbs the transmitted message. 

Keeping this advantage of quantum physics for QC in mind, any QC-protocol uses mes- 
sages entirely composed of an incompatible set of quantum states or so called quantum 
alphabet that consists of incompatible "letters" . Various protocols of QC are distinguished 
in essence only by different alphabets, which ensure secure message transmission up to an er- 
ror level that determines the protocol efficiency. Analyzing distortions in received messages 
one can reveal an eavesdropping attack, but in order to raise the information transmission 
rate it is necessary also to counter such attacks. All discussed in the literature QC-protocols 
have relatively low, about 15%, quantum bit error rate (QBER) [1] above which they do 
not ensure secure transmission. Ideally, all perturbations in the transmitted information are 
caused by an eavesdropper, but in reality imperfections of apparatus used for realization of 
the QC-protocol and external sources of noise (besides the eavesdropper) also perturb the 
information. 

For the optimal efficiency analysis of various protocols different efficiency criteria are 
used [8], which is inconvenient for the objective comparison of the protocols. In this paper, 
we will use most appropriate criteria based on the classical Shannon information approach 
estimating amount of information transmitted through the information channels of the QC 
scheme [9]. In QC, typical information system includes three basic components, Alice, Bob, 
and Eve (the conventional names for the sender, receiver, and eavesdropper, respectively), 
which communicate through a quantum channel. Despite the communication nature between 
Alice, Bob. and Eve is quantum, they in the final analysis exchange classical information. 
Therefore, the classical Shannon information is a valid measure for a quantitative analysis of 
the quantum cryptography protocols, which corresponds to the joint probability distribution 
of the measurement results (which are classical) in the quantum system Alice-Eve-Bob. 

An alphabet used for a message encrypting is formed commonly by selection of a set 
of quantum states at the input and output of the quantum channel. The selection rules 
determine different QC-protocols. For example, QC-protocol proposed in 1992 by Bennett, 
hence the name B92 [4] , uses only two quantum states, which is the minimum limit of number 
of incompatible "letters" composed the alphabet. The first protocol for QC proposed in 1984 
by Bennett and Brassard (BB84) [3] gives another example of protocol using four quantum 
incompatible states. 

In another limiting case, when selection of quantum states is not performed and, there- 
fore, the alphabet consists of all states of the Hilbert space, we have a new QC-protocol, 
which is analyzed in this paper. It is shown that this protocol surpasses all known QC- 
protocols by a number of criteria. For instance, its critical QBER exceeds that one for the 
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BB84 protocol and generalization of our protocol to the case of multidimensional Hilbert 
space further significantly improves the critical QBER. This means that the new protocol 
can basically work at any level of external errors or eavesdropping attacks, which is a new 
feature of the QC-protocols. 

II. COMPATIBLE INFORMATION AS A QUANTUM INFORMATION 

MEASURE IN QC-PROTOCOLS 

In QC, Alice {A), Bob (B), and Eve (E) are the different, kinematically independent 
quantum systems. Thus, the quantum events related to these systems belonging to the 
different Hilbert spaces are mutually compatible. Due to this property, any pair of quan- 
tum events at the input and output of the quantum channel can be considered classically. 
Quantum specific of the channel is revealed then only in the form of intrinsic quantum 
uncertainty of events at the input and output of the channel. We will call information re- 
lated to the mutually compatible events in two quantum systems the compatible quantum 
information [10, 11]. A natural quantitative measure for the compatible information is the 
standard mutual Shannon information functional of the classical input-output (Alice-Bob) 
joint probability distribution Pab'- 



where S[P] is the classical Shannon entropy functional for P — Pa, Pb, and Pab [9]- 

In quantum theory, like in the classical theory of information, one has to clarify which 
quantum events are used for the information exchange between quantum systems and to 
define a set of elementary events of which any message is composed. Elementary events for 
a given quantum system are represented by the wave functions or state vectors of the system. 
Mathematically, a choice of basis events can be given by defining a set of positive operators 
El, representing a non-orthogonal expansion of unit operator [12, 13], which is an analog of 
average classical indicator functions of a complete group of classical random events, which 
are normalized to the indicator of the reliable net event (with the probability equal to unity) 
and can be written in quantum case as the unit operator: 



For simplicity, we will consider in the following two-dimensional spaces, if not defined oth- 
erwise. 

Two limiting cases of the compatible information — limiting selected and non-selected 
information — are defined by two limiting cases of the unit operator expansion — two- 
component orthogonal [14] 



^abIPab] — Sa[Pa] + Sb[Pb] — Sab[Pab], 



(1) 




(2) 



1 = 



(3) 



and continual non-orthogonal [11] 




(4) 
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where |^) and are the arbitrary pair of orthogonal wave functions and dT4 = 
sin 9 dO dip / {211) with the standard angular parameters on the Bloch sphere. 

The selected information determines an information link between two quantum systems 
A and B with the joint density matrix pab through the selected set of orthogonal quantum 
events. The orthogonal basis determined by the unitary two-parametric transformation 
Ua{ol) and Ub{P) in quantum systems A and B, respectively, can be chosen differently and 
the selected information also depends on the choice made: 



P)-y: pfB% I) log, (5) 



where parameters a — {9i,ipi) and /? — {62, (f 2) are given by the standard Bloch sphere 
angles. 

Joint distribution P'^^{k,l) = Tr^B(^^(/c) ® E^{1))pab is defined on the basis states of 
the input (Alice) and output (Bob) of the channel |/)^ numbered by two indices k and 
I. These states are the orthogonal basis states of respected Hilbert spaces Ha and Hb- 

For the non-selected information, the information exchange undergoes through all equally 
participating in the exchange states. In this case, basis states of the information channel 
arc all wavefunctions of the Hilbert spaces of all participating in the exchange quantum 
systems. The respected non-selected information is then given as 

;..^//...(d.,d«.o,.^§|^^, (6, 

a P 

where PAB(da,d/?) = TrAB(^A(da) ® EB{df3))pAB, EA{du) = \u)^{u\^dV^. 

Note that the non-selected information is equal to the selected one, which is averaged 
over all orientations of the orthogonal bases: 



lAB 



IJlABidaM^^, (7) 

a /3 



III. QC-PROTOCOL EMPLOYING ALL STATES OF THE HILBERT SPACE OF 

THE CRYPTOGRAPHIC SYSTEM 

Key idea of QC is that secure quantum information channel is used first to transfer a 
secret key from Alice to Bob, which is then used to encrypt messages transmitted via an 
insecure classical channel. The quantum channel over which the message out of which the 
secret key will be extracted is transferred can be eavesdropped by Eve who can perform 
any physically allowed transformations gaining information about the transferring message. 
The purpose of Alice and Bob is to establish a secure connection, which prevents copying of 
useful transmitted information by Eve. li was proved that such secure connection is possible 
if the amount of information Bob received from Alice exceeds information Eve received either 
from Alice or Bob [15]. This condition can be written as 
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Iab > m.ax{lAE, I be)- (8) 

If the condition (8) is fulfilled, it is possible with the help of special methods of encrypt- 
ing/decrypting the information to reduce up to zero the amount of useful information Eve 

can gain eavesdropping the quantum channel. 

Eve, in her turn, also tries to use optimal strategics of eavesdropping at the given level 
of interference, i.e.. Eve tries to gain maximum information about the transmitting message 
minimizing the error level she causes. 

All known QC-protocols using finite-dimensional spaces of states are built on the alpha- 
bets with the finite discrete set of incompatible quantum "letters", which can be realized 
as the pure states of a quantum system. In this paper, wc suggest a qualitatively new QC- 
protocol, which is based on the alphabet including all states of the Hilbert space. In other 
words, this alphabet consists of an infinite number of quantum "letters" , which are formed 
by arbitrary superpositions of orthogonal basis states of the Hilbert space Ha- 

Let us first consider the case of two-dimensional space (multidimensional case is consid- 
ered in section IV). 

Elementary step of the QC-protocol that is transmission of a single "letter" or state from 
Ahce to Bob can be outlined as follows: 

1. Alice transmits to Bob via a quantum channel a randomly chosen state Let 
us assume that the Alice's state |q;) is totally entangled with the transmitting state 

\P) and is, for example, the antisymmetric Bell state || — )) = (!«) P) — \a) \ j3))/-\/2, 
which means that Alice perfectly knows the transmitting state. 

2. Eve eavesdrops the channel performing an unitary transformation Ube with her initial 
state |0)^ and with transmitted by Alice to Bob state |/?)^ and readily measures her 
final state. 

3. Bob reads the perturbed state using for the measurement an arbitrary projector be- 
cause he has no a priori information about the received message. 

When transmission of the message is completed, Alice and Bob disclose part of the mea- 
surement results transmitting them over an insecure classical channel in order to determine 
the mutual probability distribution, which is then used for calculation of an average amount 
of transmitted information per an elementary step of the QC-protocol. After that, disclosed 
results are discarded and not used for further generation of a secret key. If the security 
condition (8) is fulfilled, Alice and Bob decide that the secret key transfer is completed, oth- 
erwise the transmitted key is not used. Note that the described protocol does not require 
bases reconciliation of Alice and Bob, i.e., selection of only that part of the message for 
which Alice and Bob used the same measurement projectors, via an additional information 
exchange over the classical channel. 



A. Information analysis of the protocol 

For information analysis of the suggested protocol let us first calculate the amount of 
information Bob received from Alice and Eve received from Alice and Bob at the condition 
of optimal eavesdropping. 
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Initial state of the quantum system Alice- Eva-Bob p^^be — Pab ® 10)^(01^;' which is 
described by the tensor product of the entangled antisymmetric pair Alice-Bob = 
II — 11^^ and an initial Eve's state |0)^, is transferred after eavesdropping the chan- 



' AB 



nel by Eve into the final state that is an entangled state of Alice, Bob, and Eve, p\be'- 

.(1) Ube 42) 

Pabe ^ Pabe- 

We can then assume (without reducing the generality of our consideration) that the 
unitary transformation Ube performed by Eve has the form: 



|0)s|0>^^|0)5l$oo>^+|l)sl^oi>^ 

Ube 



|0) 



E 



|0)bI^io>e + |1)sI^ii>e- 



(9) 



The unitarity imposes the following restrictions, which are due to the orthogonality and 
normalization conditions: 



($00 I $io) + ($01 I ^ii) = 0, |$oor + |* 



oil 



1$ 



10 1 



+ 1$ 
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1. 



(10) 



It was suggested in reference [8] based on the numerical estimations and then proved 
in reference [16] that in the QC protocols BB84 and B92 the Eve's state at the optimal 
eavesdropping lies in two-dimensional Hilbert space. This is also true (and can be proved) 
for our QC-protocol. Therefore, the states can be written with the help of condition 
(10) as a superposition of two basis states: 



where the transformation parameters 



/l'^oo)\ 




1 7oo 7oi \ 




'^'oi) 




7io 7ii 




$10 ) 




7ii 7io 


V 






\ 7oi Too / 



0)^ 
^)e 



(11) 



Imn = (-1)"^" COS {9 - m|) COS ((^ - n|) 

are determined via two angles 9, ip on the Bloch sphere. 

Resulted bipartite density matrices Alice-Bob, Alice-Eve, and Bob-Eve received by av- 
eraging of the three-partite density matrix over the third system enable us to calculate the 
respective mutual information: 



(12) 



In our QC-protocol Alice sends Bob any pure state with equal probability and neither 
Bob nor Eve have an a priori chosen basis for the measurement, thus both Eve and Bob 
use each an arbitrary chosen basis. After averaging over large number of measurements we 
receive due to the equation (7) that the non-selected information is exactly the information 
measure for our cryptographic system. 



42) 

Pab = 




Iab 


42) 

Pae = 




Iae 


42) 

Pbe^ 


Tr^P^L - 


Ibe 
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B. Calculations results 



Results for the mutual Alice-Bob, Alice-Eve, and Bob-Eve non-selected information {Iab, 
Iae, and Ibe, respectively) calculated with the help of equations (6), (9), (11), and (12) are 
shown in figure 1 versus parameters 9 and (p controlled by Eve. One can clearly see from 
the figure that for all values of ^, (p we have Iae ^ ^be, thus we will focus in the following 
only on Iae- 

The optimal eavesdropping condition requires that we look for the maximal Iae = 
Iae{9,ip) at the given value of Iab = -^ab(^, V')- Detailed analysis of data in figure 1 
shows that the optimal eavesdropping at any level Iab can be realized at 9 — 7r/A — (fi, which 
corresponds to the solid line in figure Id. 

For most purposes it is enough to consider only two-dimensional plots of Iab{9) and 
Iae{9) along the solid line 6* = 7r/4 — which are shown in figure 2. From analysis of this 
figure one can see that at ^ = the level of Eve eavesdropping attacks and the respected 
losses of information are equal to zero. At 9 — tt/A the intervention of Eve is maximal and 
she acts, in fact, as Bob gaining maximal possible information. 

The condition for the protocol to be a secure one, Iab > Iae, is fulfilled up to a certain 
critical value = 7i"/8, which is the intersection point (1) of the curves for Iab and Iae 
in the figure 2. At this point, the QBER q = 1 — Trp^^^ p^^\ has the critical value of 
go — sin(7r/8) ~ 0.15, which is equivalent to the QBER value provided by the BB84 protocol 
[1,3]. The respected value of the compatible information is equal to Iq — Iab{9 — 9q) ~ 0.11 
bit. 

As it is demonstrated in reference [8], the QBER is not always an adequate characteristic 
of the degree of Eve eavesdropping attacks, for instance in the B92 protocol. Therefore, we 
suggest to use another characteristic, the compatible information error rate (CIER), which 
naturally reflects in term of the compatible information the degree of Eve interference to 
the transmitting information: 

g = i--^G [0,1], (13) 

-'max 

where / is the compatible information Iab with the presence of eavesdropping and /max its 
maximal possible value without Eve attacks. By contrast with QBER {q), CIER {Q) is the 
most adequate parameter for the information properties of the QC-protocols. 

Without Eve eavesdropping attacks, both parameters q and Q are equal to zero, which 
means that there are no transmission errors. At the maximal level of Eve interference 
with the transmitting information, we have Q = 1 and q = 0.5, which correspond to the 
maximal possible level of errors caused by Eve. At the critical point 9o, where the amount of 
information gained by Eve is equal to the amount of information received by Bob, Qq ~ 0.4 
and qo ~ 0.15. For our QC-protocol, the larger critical value Qo the better stabihty of the 
protocol to the errors caused by Eve and, therefore, better information properties. Thus, 
the protocol ensures the security of transmitted data even at essential errors rate during the 
data transmission. At the error level exceeding critical, i.e. at Q > Qq, the protocol does 
not ensure security of transmitted data and Alice and Bob decide that the transmission is 
not completed. 

In suggested QC-protocol the requirement of bases reconciliation for Alice and Bob is 
lifted because even with no selection of quantum states made at the Bob's end he receives 
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about 0.28 bit for every elementary step of the QC-protocol, if there is no external noise 
during data transmission. However, one can significantly improve stability of the protocol 
for a noisy quantum channel reconciling the basis states. 

After transmission of all data through a noisy quantum channel Alice and Bob can 
select only those transmitted data for transmitting which they used approximately similar 
orthogonal bases. In our case, the set of basis states is the continuum, thus it is necessary to 
split it into several areas and count the bases similar, if they are in the same area on the Bloch 
sphere. As a result of such selection, Alice and Bob will receive without any intrusion of Eve 
maximal information value of about 1 bit during one elementary step of the QC-protocol. 
This can be clearly understood because for an initial state of the Alice-Bob system in the 
form of antisymmetric Bell state the mutual selected information is equal to unity when use 
similar oriented bases of Alice and Bob. One can suppose that Eve does not affect the data 
selection with the reconciling bases and does not use additional transformations after the 
bases have been reconciled. Then, she gains no additional information. 

Information that Bob receives from Alice after the bases reconciliation is shown in figure 
2 (dashed line). The critical error rate Q is then significantly increased and is of the order 
of value Qq ~ 0.81 and for the QBER we have go — 0.42, which is much better than for all 
known QC-protocols. 

Note that the bases reconciliation procedure significantly increases the number of mes- 
sages transmitted over an insecure classical channel, which in the limit of infinitively small 
areas on which we split the continual quantum alphabet grows up to infinity. Respectively, 
the number of selected messages transmitted through a quantum channel is decreased. It 
is not necessary, however, to infinitely increase the accuracy. As a rule, errors during the 
data transmission have typical for a specific experimental QC setup finite level. Therefore, 
for the bases reconciliation it is sufficient to increase the accuracy according to the external 
conditions up to the level that ensures the error rate less than the critical one at which the 
QC-protocol guarantees the secure transmission of data. 



We can fundamentally improve the properties of suggested QC-protocol using multi- 
dimensional Bob's and Ahce's spaces {D > 2). In multidimensional case, the maximally 
possible amount of mutual selected information is equal to 1^^^^ — logg D and grows in- 
finitely at D ^ oo. Maximally possible amount of non-selected information is equal to the 
volume of accessible information [17]: 



which in the limit D ^ oo is restricted by the value of ~ 0.61 bit. 

After reconciliation the Alice's and Bob's bases the amount of information in the system 
Alice-Bob is given by maximally possible selected information, whereas in the Alice-Eve 
system — by the maximally possible non-selected information. Then, critical level of errors 
in the limit of ^ oo is equal to unit: 



IV. MULTIDIMENSIONAL CASE 




k=2 
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'o* = 



1- lim 



accessible 



~ 1 — lim 



0.61 



(14) 



D-*oo log2 D 



= 1. 



D^oo 



max 



This means that increasing the dimensionality of the Alice-Bob system one can reach the 
critical error rate (QBER or CIER), which exceeds any given value. The multidimensional 
spaces of Alice and Bob can be realized using block coding when information is transmitted 
simultaneously with the help of several qubits. 

Fundamental advantage of the suggested QC-protocol that employs all states of the 
Hilbert space is that it can work, in principle, at any imperfections or noise in the quantum 
channel (either internal or external) and has no any critical CIER value after which the 
protocol becomes insecure. For any given CIER value one can calculate (from technical 
point of view, calculations in the case of multidimensional space can be readily done) the 
required dimensionality of the Alice-Bob space in order to meet this value of CIER. Essen- 
tially more difficult is the question about Eve's transformation structure to perform optimal 
eavesdropping in the multidimensional case, but the outlined above result is qualitatively 
correct, despite any specific structure of the Eve's transformation. 

V. EXPERIMENTAL SETUP FOR QC WITH CONTINUOUS ALPHABET 

In this section, we suggest an experimental setup for the QC with continuous alphabet 
"letters" of which are coded with polarization of the photons (figure 3). Then, a random 
letter corresponds to an arbitrary photon polarization. 

A source of EPR-pairs of photons, for instance an optical parametric oscillator (2) gener- 
ating pairs of photons in antisymmetric entangled state, is located at the Alice's end of the 
cryptographic setup. Alice receives one of the generated photons, another one is transmitted 
via a secure quantum channel to Bob. 

An arbitrary projector can be realized by rotation to an arbitrary angle the polarization 
plate (3) with the following measurement in the fixed basis. Photons transmitted from 
Alice to Bob are in the antisymmetric state, thus Alice knows exactly, after the photon 
measurement on her end, that photon she sent to Bob is an orthogonal state to that one 
measured by Ahce. As a result of the outlined procedure, Alice sends to Bob a randomly 
chosen quantum "letter". 

Likewise, Bob for the measurement in an arbitrary basis first rotates polarization of the 
incident photon by polarization plate (3) to the angle value of which he receives from Alice 
over an insecure classical channel (not shown in the figure) and then performs measurement 
in the fixed basis. 

A case of multidimensional spaces of the quantum channel input and output can be 
realized when information is transmitted with the help of several entangled qubits (photons). 
This, however, is an experimental difficulty to generate, operate, and measure arbitrary 
states in multidimensional spaces, i.e., difficulty to generate and operate multiple entangled 
photons. 
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VI. CONCLUSIONS 



In conclusion, a new QC-protocol based on the quantum alphabet with infinitive num- 
ber of "letters" (i.e., employing all the quantum states of the Alice-Bob quantum system) 
is proposed. It has a number of advantages in comparison with other known QC-protocols. 
Even in two-dimensional case the protocol shows an essential increase of the QBER. In mul- 
tidimensional case, the protocol has a fundamental, qualitatively new feature, which allows 
secure data transmission through practically any noisy quantum channel. For estimation of 
the Eve's intervention into the data transmission through a quantum channel we use classi- 
cal mutual Shannon information-based criterion, which adequately reflects the information 
aspect of the eavesdropping and can be effectively used for both constructing and analyzing 
the QC-protocols. 
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FIGURES 




FIG. 1. Alice-Bob (a), Alice-Eve (b), and Bob-Eve (c) mutual Shannon information versus Eve's 
eavesdropping parameters 9, if. Figure (d) shows results of figure (a) for the Alice-Bob mutual 
Shannon information {Iab) as a contour plot; solid line indicates the optimal eavesdropping. 
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FIG. 2. Alice-Bob (dotted and dashed lines for reconciliated and non-reconciliated basis states 
of Alice and Bob, respectively) and Alice-Eve (solid line) mutual Shannon information at the 
optimal eavesdropping condition. 
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FIG. 3. Experimental setup for the QC with continuous alphabet. Laser (1) pumps an optical 
parametric oscillator (2), which generates a pair of entangled photons one of which is transmitted 
then to Alice and another one, via a quantum channel (6), to Bob. Measurement part of the 
cryptographic scheme consists of a polarization plate (3) that rotates polarization of the incident 
photon, prism (4), and photon counting detectors (5). 
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